The artifact includes tests and a substantial README, but its declared MIT license conflicts with the detected GPL-3.0 license file. No security policy is published, increasing transparency concerns for a database integration.
38%
Total Score
50
60
75
The latest release was published in May 2022, with no releases in the last 12 months. This long publishing gap materially raises abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the prolonged release gap and weak evidence of ongoing maintenance.
A license file is present, but it is detected as GPL-3.0 while the manifest declares MIT. The release is licensed, yet the mismatch creates a meaningful compliance concern.
The repository has no security policy. That is a transparency gap for a database driver, although it does not by itself show unsafe code.
The package is on a stable major line, but the indicator reports latest version 1.1.0 while the assessed release is v1.5.3. That inconsistency reduces release transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^2.7 | — | — |
smi2/phpclickhouse Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.